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GNU is 

Not 

Unix 



Exploring the 
25-year history of 
Stallman's Project 



Dawn of a new era 
for GNU Compilers 

After 25 years, plug-in tech 
comes to C, C++ and Fortran 



BY ALEX HANDY 

When Richard Stallman began 
writing Bison in 1983, he was 
only trying to build the bits of 
an operating system he would 
need to write another operating 
system. But that recursive goal 
was no stranger than the recur- 
sive name he would create for 
the software he would eventu- 
ally create: the GNU Project, 
where GNU is standard for 
"GNU is Not Unix." 

And now, 25 years later, one 
of the most important tools to 
come out of the GNU Project's 
drive for the GNU Operating 
System — the GNU Compiler 
Collection — has received 

approval from the Free Soft- 
ware Foundation to begin work 
on a plug-in architecture. 

The GNU Project is made up 
of "a lot of different programs," 
reminisced Stallman. "Since 
many of them are a lot of work, I 
kept looking for opportunities to 



start with something that exist- 
ed, rather than start from zero. 
But most of those opportunities 
I found didn't actually work." 
And so he began to build his own 
solutions. 

"I found a compiler to start 
with called Pastel," Stallman 
explained. "It was basically Pas- 
cal, to which had been added 
every kind of language feature 
you could imagine. It had a 
compiler. I began extending it to 
handle C and to support the 
[Motorola] 68000 processor, as 
well as the VAX [minicomput- 
er]. And I got it working on 
compiling C programs on the 
VAX. It could compile its own C 
front end." 

So far, so good... but then 
came the limitations. "When I 
tried to port [the compiler] to 
the 68000, I got code that 
seemed to more or less work. I 
tried to get it to run, but it was 
continued on page 12 ► 



Downturn strikes 
AMD, Intel, Microsoft 

Economic realities hit close to home 



BY DAVID WORTHINGTON 

Microsoft has followed AMD 
and Intel as the latest industry 
heavyweight to order mass lay- 
offs as a cost-cutting measure in 
response to worsening economic 
conditions. 

In its annual report to share- 
holders, Microsoft disclosed that 
it would dismiss 5,000 people 
over the next 18 months. A 
Microsoft spokesperson stated 
that the layoffs began immedi- 
ately with 1,400 employees. The 
rest will gradually take place 



across the company in finance, 
human resources, IT, legal and 
corporate affairs, marketing, 
R&D, and sales. 

Microsoft currently employs 
approximately 94,600 worldwide, 
not counting the layoffs that 
already occurred following the 
report. 

"Every division is assessing its 
portfolio and prioritizing invest- 
ments based on the best opportu- 
nities in the current economic 
environment," said the spokesper- 
son. "While there are no major 



products being cut outright, we 
will consolidate some products 
and groups where it makes sense." 

The cost cuts Microsoft has 
proposed, including the layoffs 
on top of cuts in facilities and 
marketing, could lower its oper- 
ating expenses by US$1.5 bil- 
lion, according to a UBS Invest- 
ment Research report. 

Microsoft also announced 
results for its fiscal second quar- 
ter 2009 that fell well below 
earning guidance. While still 
continued on page 16 ► 



Microsoft, SFLC spar 
over GPL challenges 
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How accessible is the most 
popular open-source license? 
Both sides come out fighting 



BY DAVID WORTHINGTON would have required Microsoft Ramji has taken a much more 

Microsoft acknowledges that to make its entire software port- pragmatic view of the license 

the GNU General Public folio open source. It has since than Ballmer once did. He does 

License is an important license, enabled GPL-based technologies not call it a cancer, but he main- 

but the company believes that it through partnerships and has tains that while the GPL is 

is challenging to work with. softened its viewpoint. important due to the volume of 

That's the view of Sam Ramji, GPL is a "copyleft" license, a code licensed under it, it only 

Microsoft's senior director of scheme that requires subsequent represents two out of the 54 

platform strategy. authors who use GPL-based Open Source Initiative-approved 

Nearly eight years have passed code in their applications to sur- open-source licenses, 
since Microsoft CEO Steve Ball- render some of their intellectual However, that assertion over- 

mer infamously declared Linux property rights in order for con- looks the quantity and impor- 

to be a "cancer," and that the tributions to be distributed back tance given to GPL-licensed soft- 
GNU General Public License to the open-source community. continued on page 16 ► 
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JavaFX cooks up rich client Java 



Rendering RIAs 

Fourth in an occasional series 



Sun's new rich Internet platform is already winning praise 



BY JEFF FEINMAN 

When Jim Weaver was looking 
to teach his grandson how to be 
a programmer, he wanted to 
create a little interactive world 
through which the youngster 
would be able to navigate. 

In creating a user interface 
that would allow his grandson 
to drag and drop animated 
icons and objects onto a layout 
featuring Thomas the Tank 
Engine or other cartoon char- 
acters, Weaver tried Sun 
Microsystems' new JavaFX 
platform because it solved some 
longtime Java problems. 

"That was a first little pro- 
gram for him that would teach 
him how to program," said 
Weaver, who serves as senior 
vice president for Marion, Ind.- 
based digital media provider 
Veriana Networks. "I wanted to 
generate JavaFX code from the 
interface. After I got into 
JavaFX, I found it solved a lot of 
the problems I had faced over 
the years in being able to do rich 
client Java. Attempts that were 
made to do rich client Java since 
Java was created in 1995 were 
pretty much thwarted by deploy- 
ment problems." 
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Jim Weaver used JavaFX to help visual tool provider Maiden Labs create 
the 6th space user interface. 



Weaver never actually creat- 
ed that program using JavaFX 
(he settled on MIT's kid-friend- 
ly Scratch programming lan- 
guage), but his enthusiasm for 
the platform hasn't waned. 

Sun's eye was on solving 
many issues around rich Inter- 
net applications (RIAs) when it 
released version 1.0 of JavaFX in 
late 2008. The platform targets 
Windows and Mac OS X, and 
can be used to construct both 
Web and desktop applications. 
Java video codecs enable video 
playback, and there are plug-ins 
for Eclipse and NetBeans. 



Sun executives believe that 
JavaFX is in a position to 
replace PHP as a presentation 
layer and that the platform has 
a more replicable development 
model than other RIA plat- 
forms like AJAX. But with the 
other major RIA platforms, 
such as Adobe Flex, AJAX and 
Microsoft Silverlight having a 
head start, there may be spots 
where Sun can be polished in 
coming releases. 

JavaFX's biggest benefit is 
its ability to call millions of 
Java classes with its rich client 
Java, according to Weaver, 



Microsoft donates code to Stonehenge 

Project tests Web standards interoperability 



BY DAVID WORTHINGTON 

Several months after joining the 
Apache Foundation, Microsoft 
has made its first code contri- 
bution to an Apache ^^^™ 
project. The project, 
known as Stonehenge, 
is made up of compa- 
nies and developers 
seeking to test the 
interoperability of Web stan- 
dards implementations. 

Stonehenge contributors are 
expected to provide sample code 
for applications that work across 
platforms, and to work around 
differences in their respective 
standards implementations. 

The Stonehenge incubation 
project was announced in 
November 2008 at ApacheCon. 
Apache, Microsoft, Red Hat and 
WS02 are listed as contributors. 

Microsoft's contribution to 
Stonehenge is a sample applica- 
tion called StockTrader 2.0. 
StockTrader implements WS-* 
standards and was designed to 
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demonstrate service-oriented 
architecture design principles. 

"In general, this is a big 
issue. The whole point of stan- 
dards is to provide for 
interoperability, but so 
many are implemented 
in slightly different 
ways that the desired 
interoperability is not 
achieved," said ZapThink man- 
aging partner Jason Bloomberg. 
In many ways, that lack of 
standards interoperability is 
slowing down Web services 
efforts, and SOA has now out- 
paced Web services due to the 
standards challenge being 
faced, he added. 

Standards interoperability is 
what allows mobile phones to 
work anywhere in the world, 
Bloomberg noted. "Imagine 
what has to happen to make that 
work. Handsets are working 
with local providers across infra- 
structures. In IT, there is noth- 



knives and bearskins compared 
to the telecommunications 
world's leverage of standards." 

The Apache Foundation is 
not the only group working 
toward standards interoperabili- 
ty. In December, the Web Ser- 
vices Test Forum, an industry 
group that tests standards-based 
integrations, went public with 
its work. Its members include 
Cisco, IBM, Oracle, Red Hat, 
Software AG and TIBCO. 

"Stonehenge and WSTF 
were conceived independently, 
and there may be some over- 
lap," said Kamajit Bath, princi- 
pal program manager of the 
Microsoft interoperability tech- 
nical strategy team. "Microsoft 
sees them as potentially com- 
plementary, with Stonehenge 
focused on developing applica- 
tion code to illustrate how to 
use the Web services infrastruc- 
ture to build interoperable ser- 
vices that address real world 



ing like that. It is still using stone scenarios." 



who also writes a JavaFX blog 
at learnjavafx.typepad.com. 
JavaFX compiles class files and 
runs in Java virtual machines. 

JavaFX also lets coders 
declaratively script a UI. Weaver 
said JavaFX's JSON-like syntax 
makes it very easy to do, and a 
developer can declare a UI 
scene graph very intuitively. This 
makes it easy for people that 
aren't necessarily experts with 
Java to script and create UIs. 

"It's a pretty rich library now 
in 1.0 as far as the ability to 
put together UIs, and it has a 
rich API for doing graphics," 
Weaver said. "Its [strengths are] 
being able to animate, do 
effects, and parse XML and 
JSON for being able to do 
mashups or communicate with 
the back end." 

JavaFX's ability to improve 
Java deployment and make Java 
leaner was something that drew 
Jeremy Chone, CTO of Nex- 
aweb, to the platform. Nexaweb 
provides an RIA framework 
based on XML that enables 
developers to create applica- 
tions similar to Swing, which is 
Sun's widget toolkit for Java. 
Chone said that JavaFX has a 
lean and simple client, and he 
praised the platform's UI. 

"When you work with UIs, 
you want to have a language 
that is a little bit more sugar- 
coated, and you want to have an 
easy way to do certain tasks, like 
creating new objects and sets," 
Chone said. "That is one of the 
good things that JavaFX does." 

GROWING UP TO DO 

Naturally, because JavaFX was 
released in late 2008, it doesn't 
have the maturity level of some 
of its RIA counterparts. Adobe's 
Flex was first released in March 
2004 and is currently in version 
3.2. AJAX started to take off in 
2005. Microsoft's Silverlight hit 
version 1.0 in April 2007 and is 
now in its second version. 

As JavaFX moves toward its 
next phase, there are some 
changes that developers would 
like to see. Weaver said that 
JavaFX could use a richer selec- 
tion of layouts. He noted that 
the platform currently has a 
couple of layout managers, 
among them HBox and VBox, 
which are graphical nodes that 
offer a simple horizontal and 
vertical layout, respectively. 




However, this is an area that 
Weaver thinks can be improved. 
"I'd like to see a richer set of 
layouts, whether it's from Sun or 
a third party," he said. 

Another shortcoming in the 
first release of JavaFX, he said, 
is that most of the UI controls 
are from Swing. Weaver would 
rather see a style-sheet model 
in the vein of CSS (Cascading 
Style Sheets). 

Like Weaver, Chone men- 
tioned JavaFX's JSON-like syn- 
tax, but he said he had mixed 
feelings about it. 

"I am a little biased towards 
XML, but the fact that Sun 
decided to go with a JSON-like 
syntax is better than designing in 
code," Chone said. "At the same 
time, it's a little bit harder to 
build tools around. The scripting 
can sometimes be a little tricky 
because, as a Java developer, the 
scripting language is not true 
Java. A lot of Java developers 
I've talked to are disappointed 
that Sun didn't hang on to the 
core language." 

Open-source projects work- 
ing on patching up some of the 
perceived deficiencies in 
JavaFX. One is JFXtras, which 
creates add-ons and utilities for 
the JavaFX script language. 
Add-ons include the JFXtras 
Grid, which has a layout con- 
tainer for JavaFX nodes and 
wrapped Swing components, as 
well as a unit testing facility for 
writing JavaFX tests. JFXtras 
plans to release features like 
serialization to and from XML, 
graphing and charting for busi- 
ness applications, and a variety 
of UI components like sliders 
and tables. 

Weaver, who is involved in 
the JFXtras project, said that the 
JavaFX community has a good 
relationship with the project 
when it comes to creating miss- 
ing components. "On the sub- 
ject of layouts, for instance, 
there is nothing in JavaFX now 
that is analogous to JFXtras 
Grid," he said. "It is good that 
Sun will both get input from the 
community and create their own 
layouts and components." I 
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...which can display 2D & 3D charts 
with presentation quality, without sacri- 
ficing speed. 
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...which contains a complete set of 
charting and gauge types, designed to 
meet even the most compelling data 
visualization tasks. 

With so many different charts and gauges at your 
fingertips, you will never find yourself at a stale- 
mate. If there is any chart or gauge you need - 
we've got it. 
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...which has a well designed and pol- 
ished object model, allowing you to 
extend and customize it. 

Scalability is what you need. We guarantee it! Just 
as we guarantee, that our API is as versatile as 
they come. 
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...which contains an unmatched set of 
examples, with source code, that will 
help you get started quickly in both 
ASP.NET and Windows Forms. 

Sometimes it's beginner's luck, sometimes it's 
having the best help around. Scroll through our 
examples, check out the source code, and you're 
already halfway done! 
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PDT 2.0 gets a new engine 



Under the hood, PHP Development Tools has a new motor 

BY ALEX handy tion released PHP Development another Eclipse project, rather like GUI, said the PDT team. 

Sometimes a new engine can Tools 2.0. The new version than the previous engine written Roy Ganor, project lead for 

make all the difference. In late builds on top of the Dynamic by the PDT team. The result is a Eclipse PDT and product lead 

December, the Eclipse Founda- Language Toolkit (DLTK), more responsive and Eclipse- at Zend Technologies, said that 




the team for 2.0 had different 
goals than 1.0. "We used the 
DLTK, which provides a good 
infrastructure, similar to the 
Java Development Tools, which 
provide modeling and better 
caching and indexing capabili- 
ties. This enabled us to provide 
more object-oriented features, 
like type parity and other stuff 
that most of the PHP users are 
not used to getting in the simple 
editors that are provided today 
in the market," said Ganor. 

PDT 2.0 is the first version of 
the tools to offer a type hierar- 
chy view, giving developers a 
better look at how their objects 
stack together. It also adds type 
and method navigation, which 
gives users more powerful ways 
to search code for specific items. 

The engine overhaul also 
contributed to improved code 
assist features. Code comple- 
tion has been reworked to make 
it more accurate, and a new 
indicator has been added to 
help developers searching for 
element references. 

PDT will take part in the 
Eclipse 3.5 Galileo release train, 
a first for the project. The PDT 
road map also includes some 
other firsts, particularly what 
Ganor hopes to be the first IDE 
to support PHP 5.3 s features. 

"First of all, I think that 
usability should be improved in 
any project," said Ganor, dis- 
cussing the aspects of PDT he'd 
like to improve in the next 
release. "PDT can also be 
improved by adding more sup- 
port for object-oriented pro- 
gramming in PHP. But the most 
important thing we're going 
toward is supporting PHP 5.3. I 
hope that we'll be the first pro- 
ject to support those features." 

Ganor also wants to collabo- 
rate with other Eclipse pro- 
jects, along the lines of PDT 
2.0 s DLTK influences. 

"We have also deployed and 
used the Web Tools Platform, 
which is a great community at 
Eclipse that enables users to 
have Web tools like HTML, 
XML and other stuff that is use- 
ful for PHP developers," said 
Ganor. "This is a great example 
of how we leverage existing 
projects in Eclipse. Other pro- 
jects, like Data Tools and Mod- 
eling are really good projects 
that we collaborate with." 

According to Zend Tech- 
nologies, previous versions of 
PDT have been downloaded 
over a million times, making it 
one of the most popular Eclipse 
projects. Version 2.0 is available 
now at www.eclipse.org/pdt. I 
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Microsoft licenses Web 
Sandbox under Apache 2.0 



BY DAVID WORTHINGTON 

Microsoft's Live Labs team 
released last month the source 
code of its Web Sandbox run- 
time under the Apache 2.0 
open-source license in an effort 
to broaden its acceptance. 

Web Sandbox, which was ini- 
tially released at Microsoft's Pro- 
fessional Developers Confer- 
ence in October of last year, 
isolates Web content, such as 
advertisements, mashup compo- 
nents and gadgets, to help devel- 
opers provide higher service 
quality and greater security. 

Aside from security, Web 
Sandbox normalizes the behav- 
ior of browsers to provide con- 
sistent W3C DOM support 
without requiring any browser 



add-ons or changes. 

Microsoft encourages devel- 
opers to contribute to Web 
Sandbox, but it does not recom- 
mend using it for production 
sites, said open-source commu- 
nity manager Peter Galli in the 
company's Port 25 blog. 

He added that Microsoft's 
goal is to drive an open standard 
that will enable interoperability 
among complementary tech- 
nologies, like script frameworks. 

"Interoperability and inte- 
gration are the two knottiest 
issues outside of security that 
confront businesses today with 
respect to network infrastruc- 
ture," said Laura DiDio, princi- 
pal analyst of Information Tech- 
nology Intelligence Corp. 



"Anything Microsoft can do to 
play nice with 'the community' 
helps the respective customers." 

Galli explained that the Web 
Sandbox was created in 
response to those limitations 
found in the current Web plat- 
form, and that Microsoft would 
like to use Web Sandbox to 
explore potential solutions. 

"Having a more secure and 
robust architecture as a founda- 
tional building block will help 
drive the next wave of Web 
innovation," said Galli. 

While Microsoft is licensing 
Web Sandbox under the Apache 
2.0 open-source license, the pro- 
ject is neither sponsored nor 
sanctioned by the Apache Soft- 
ware Foundation. I 




ERwin has come a long way over 20 years as this collection of old boxes, CDs, manuals and trinkets shows. 

ERwin gets a profiler 
for 20th anniversary 

Data modeling suite also gains Bl integrations 



BY DAVID RUBINSTEIN 

CAs ERwin data modeling soft- 
ware marks its 20th year in 
the marketplace, and the com- 
pany has unwrapped a new 
Data Profiler that lends insight 
into data stored in older sys- 
tems, allowing it to be used 
more efficiently and effectively 
in newer applications. 

The profiler is built out of 
technology from Exeros, and it 
gives CA an integrated data 
modeling, profiling and report- 
ing solution that sells for 
US$8,000, said Donna Burbank, 
senior principal product manag- 



er for the ERwin modeling suite. 

"ERwin has been a hub for 
data management, but roles are 
changing, and we've heard loud 
and clear from our users [say- 
ing], 'We're not in a silo any- 
more,' " Burbank said. 

Integration is one of the key 
points of the new release, Bur- 
bank said, so ERwin now has a 
tie-in to Business Objects' 
Crystal Reports business intelli- 
gence software. It also offers 
Open Database Connectivity 
reporting and the ability to 
exchange metadata with other 
data management tools, such as 



Cognos and Oracle Business 
Intelligence, she added. 

Burbank said that CA has 
decided to give away the Data 
Modeler for free. "We're trying 
to build up the community 
again," she said. "CA is amazed 
at the passion people have for 
the ERwin brand." 

CA is having fun with the 
anniversary celebration by ask- 
ing people to send in their old- 
est box shots of the product 
and to answer trivia questions 
such as, "Who's the first ERwin 
developer?" (Hint: It's Ben 
Cohen.) I 
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, COMPANIES , 



SAP will slash more than 3,000 jobs and freeze salaries this year 
because of the rough economy. The company's workforce will be 
reduced to 48,500 this year, the company announced; it employed 
51,536 people at the end of 2008. It said that this will save approxi- 
mately US$464 million annually, starting in 2010. 



, NEW PRODUCTS , 



Alfresco Software has created a design product for building websites, 
called Alfresco Web Studio. It offers an enterprise-class content-cre- 
ation platform and repository. The product has a Web application and 
site assembly framework for developers, and a graphical design and 
site assembly tool for business users . . . DevExpress has released the 
first public beta of its Rich Text Edit Control for Silverlight, a text- 
editing component for Microsoft's Silverlight RIA (rich Internet appli- 
cation) platform. Rich Text Edit Control offers character and paragraph 
formatting, embedded images, and predefined views for reading and 
formatting . . . Embedded product provider Geensys launched its 
ASIM simulation module for AUTOSAR Builder, a tool suite for validat- 
ing and verifying AUTOSAR systems early in development cycles. 
ASIM will initially provide VFB-Level simulation for testing software 
component sets without any hardware, according to the company. 
Geensys also launched a new version of its Reqtify embedded hard- 
ware management product, adding new third-party interface additions 
. . . IntelePeer has created an application suite based on its Appworx 
platform, which puts voice functionality into Web services and soft- 
ware applications. Company executives said that the suite offers appli- 
cations and mashups to roll out new functionality, such as automatic 
conferencing . . . Jitterbit has added interoperability with Oracle CRM 
on Demand Release 16 to its open-source integration software. Jit- 
terbit's data chunking feature helps avoid bandwidth limitations built 
into On Demand's Web service calls by moving larger data sets with- 
out any programming logic, the company said . . . Progress Software 
has created a tool that helps application developers build XML-based 
services, including SOAP and REST. Actional Diagnostics can detect 
issues early in the software development life cycle, such as policy com- 
pliance, according to company executives. Additionally, software 
developers can use the product to understand whether a service fits 
their needs before any code is written. 



, UPDATES , 



Nokia has made its Ot cross-platform application framework available 
under the Lesser General Public License version 2.1. Previously, Qt was 
available as open source under the General Public License. The com- 
pany said that this will provide developers with more permissive 
licensing and make Qt source code repositories more publicly available 
. . . SmartDraw.com has added new PowerPoint animation features to 
SmartDraw 2009.5, its business graphics software. Company execu- 
tives said that users put their presentations in SmartDraw's story- 
board mode to see them before exporting them into PowerPoint. When 
finished, SmartDraw 2009.5 users can produce turn images, anima- 
tion and text into native PowerPoint objects . . . Unit testing tool 
provider Typemock has released version 5.2 of its flagship product, 
Typemock Isolator, adding a new Microsoft Visual Basic .NET API for 
an easier start to unit testing, the company said . . . Urbancode has 
added a distributed servers feature to version 3.6 of its AnthillPro 
process automation product. According to the company, the new ver- 
sion reduces problems with slow WAN connections by enabling users 
to set up development environments based on geographic locations. 



PEOPLE 



Fortify Software has named John True as its COO. True most recent- 
ly served as vice president of sales for the Americas for storage 
provider EqualLogic, prior to its US$1.4 billion acquisition by Dell in 
2008. As COO of Fortify, True will oversee the growth of the compa- 
ny's global sales, services and channel organizations, the company 
said. I 
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Shrink the SOAR speed the transactions 



BY DAVID WORTHINGTON 

InterSystems, a maker of SOA 
infrastructure software, 

released an update to its 
Ensemble transaction-process- 
ing platform. The update 
reduces the size of SOAP mes- 



sages by using binary or binary- 
encoded XML formats, and it 
augments the security of trans- 
actions with WS- Security 1.1. 

Many of InterSystems' cus- 
tomers are in the healthcare 
industry, where hospitals, health 



systems and doctors are bound 
by the U.S. Health Insurance 
Portability and Accountability 
Act, said John Joseph, the com- 
pany's director of product man- 
agement for Ensemble. 

"Obviously the data that is 



being transferred is sensitive; 
having secure communications 
is important," said Joseph. "Per- 
formance is also important: The 
volume [of transactions] can be 
very large even within a single 
hospital network." 
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Proven 

Choose a PDF technology that is 
integrated into thousands of 
applications behind millions of 
desktops worldwide. 



Expertise 

Produce accurate and stable PDF 
documents using reliable tools 
built by experts with over ten years 
of experience. 



High-Performance 

Develop with the fastest PDF 
conversion on the market, designed 
to perform in multithreaded and 
64-bit Windows environments. 



OEM Licenses 

License and distribute products 
quickly and easily with a PDF 
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Further, Ensemble now 
offers a coordination manager 
for Health Level 7, a standard 
for exchanging health informa- 
tion. 

Having to synchronize data 
across disparate systems is not a 
problem unique to healthcare. 
As such, InterSystems has 
extended the amount of inte- 
gration protocols Ensemble 
supports, adding the e-business 
XML standards for exchanging 
business information. 

To help improve perfor- 
mance, Ensemble now allows 
third-party SNMP-based solu- 
tions and Windows Manage- 
ment Instrumentation to moni- 
tor composite applications 
through its embedded tracking 
capabilities. 

Many organizations are per- 
forming decision-making and 
data-cleansing tasks up front, 
Joseph explained. "That requires 
high-speed transactions." I 

Coverity adds 
Win32 checkers 
to code analyzer 

BY DAVID WORTHINGTON 

Coverity, code-analysis software 
developer, updated its Prevent 
static analysis suite with new 
concurrency checkers for C#, 
and it introduced checkers for 
Win32 applications that are 
written in C and C + + . 

Coverity also broadened Pre- 
vent 4.3 s support of platforms 
and tooling for Microsoft tech- 
nologies. As of this release, Pre- 
vent runs on Windows Vista and 
integrates with Visual Studio 
2005 and 2008. Mark Donsky, 
director of product manage- 
ment, said that it also works with 
Eclipse 3.2 and later. 

Coverity added C# language 
support to Prevent last July. 
The new concurrency checkers 
can discover deadlocks and race 
conditions — two common par- 
allel programming defects — in 
code at compile time, Donsky 
said. Coveritys Win32 concur- 
rency checkers can discover the 
same issues, he added. 

Prevent can provide static 
analysis for Windows Mobile, 
Windows Vista and Windows 
XP It also runs on FreeBSD, 
HP-UX, Linux, NetBSD, and 
Solaris, and it supports Java 
applications as well. 

The update is free for exist- 
ing customers. I 
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Atalasoft adds annotations to Dotlmage SDK 



BY DAVID WORTHINGTON 

A supplier of .NET imaging 
components introduced new 
document annotation capabili- 
ties to its software development 
kit for ASRNET AJAX. Also, for 
the first time, it added annota- 
tions to its Windows Presenta- 
tion Foundation (WPF) controls. 

In January, Atalasoft made 
Dotlmage 7.0 generally avail- 
able. Dotlmage is an SDK for 
annotating and viewing docu- 
ments and images in .NET 
applications. Developers may 
also use it for creating Share- 
Point Web parts that have doc- 
ument-imaging functionality, 
said Lou Franco, director of 
engineering. 

While Vizit SP is Atalasofts 
primary product for document 
imaging and viewing in Share- 
Point, it was created with 

Novell adds 
WS-Federation 
to SSO system 

BY DAVID RUBINSTEIN 

Novell has released version 3.1 
of its Access Manager with sup- 
port for the WS-Federation 
specification, providing single 
sign-on to Web applications for 
users outside a specific servers 
identity store. With this release, 
Novell focuses on interoperabil- 
ity with Microsoft's infrastruc- 
ture, particularly SharePoint. 

"Administrators are strug- 
gling to manage identities for 
different user communities, 
both within an enterprise, or for 
customers or partners," said Lee 
Howarth, product line manager 
at Novell. "These admins have 
to represent each identity, and 
it's a real headache." 

WS-Federation works with 
Active Directory, letting a com- 
pany's different units, customers 
and partners gain access to 
applications such as SharePoint. 
Users, Howarth explained, "can 
be in [an internal] identity store 
or any federated identity specifi- 
cation, and [Access Manager] 
transforms those identities into a 
set of claims that are passed up 
to SharePoint via Active Direc- 
tory Federated Services." 

Access Manager lets users 
access Novell's Access Gateway 
for authentication and single 
sign-on, Howarth said. The 
software lets admins navigate 
through identity components to 
control access, he added. I 



Dotlmage. Developers can use 
the Dotlmage SDK to develop 
custom solutions, Franco said. 

The new version provides 
AJAX-based vector annotations; 
users can add layered freehand, 
line and polygon annotations 



without requiring additional 
browser plug-ins, said Franco. 
Its WPF controls now support 
annotations, and every control 
in the Dotlmage SDK can save 
documents as PDF/A files. 
It also updates Atalasofts 



DICOM medical imaging codec 
implementation, providing add- 
ons for barcode recognition, 
OCR, the JPEG2000 and JBIG2 
codecs, TWAIN, and ISIS 
(Image and Scanner Interface 
Standard) for imaging devices. 



Dotlmage's assemblies were 
all created with .NET 3.5, and 
the AJAX SDK provides tem- 
plates for Visual Studio, said 
Franco. The templates insert 
Dotlmage controls and hook 
them up based on the wizard 
choices made by users, he 
added. "It's a better starting 
point than a blank website." I 
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Reader nominations 
open for SD Times 100 



BY ALAN ZEICHICK 

It's that time again! The editors 
of SD Times are beginning their 
deliberations, choosing the lead- 
ers and innovators who had the 
greatest impact on software 
development during 2008. SD Times 
subscribers are invited to participate by 
offering up their nominations. 

Now in its seventh year, the SD Times 
100 recognizes the top companies, orga- 
nizations and individuals. We'll be hon- 
est: It's subjective, a value judgment by 
the editors of SD Times and some of our 
closest industry advisors. 

Unlike other awards programs, we 
don't benchmark application servers, or 
count defects in operating systems, or 
consider annual sales values, or ask com- 
panies to submit flattering essays about 
themselves and their customers. The SD 
Times 100 isn't a product award or a 
marketing award. 

Instead, we work hard to identify and 
highlight where the "buzz" is. What are 
development managers thinking about? 
What are the talking heads talking about? 
What are competitors sweating about? 
That's the SD Times 100. 




As a reader of SD Times, you 
are invited to nominate the com- 
panies, organizations or individ- 
uals you believe were the trend- 
setters and thought leaders 
during calendar year 2008. You 
can submit your nomination by visiting 
our Web form (tinyurl.com/a33kx4). 

We ask you to identify your nominee 
and to help us categorize its area of lead- 
ership. We also ask you to briefly 
describe what the nominee did during 
2008 that demonstrated innovation and 
leadership in the software development 
community. What got everyone talking? 
Reader nominations for the SD Times 
100 will be accepted through March 13. 
After that, the judges really knuckle down 
to the hard task ahead. The SD Times 100 
list will be published in the June 15 issue 
of SD Times and at SDTimes.com the 
same day. 

Last year's SD Times 100 list is avail- 
able to read online (www.sdtimes.com/ 
link/32287). If you'd like background 
about the SD Times 100, that info is 
available too (tinyurl.com/b6vcpf). Thank 
you for your nominations and for partic- 
ipating in the SD Times 100! I 
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Plug-in tech for GNU compilers 



< continued from page 1 

impossible because this compil- 
er used megabytes of stack 
space." 

In those days, Motorola's 
68000 processors didn't offer 
the user control of that much 
stack space when working with 
the Pastel compiler, so Stallman 
abandoned the project and 
decided to write a new compil- 
er from scratch. He kept Bison, 
the pre-processor he'd written. 
That pre-processor, along with 
the C front end he also created, 
formed the basis of what was to 
become the gcc. 

David Edelsohn is a member 
of the gcc steering committee 
and the maintainer the PowerPC 
branch of the gcc code. By day 
he works at IBM, and he said 
that the project has been 
through a lot since the early days. 
He has been working with the 
gcc since 1988 and became a 
member of the steering commit- 
tee when it was formed in 1998. 

"gcc is a lot of exciting pro- 
jects from various constituencies 
and organizations," said Edel- 
sohn. "We're currently working 
on a project to enable link- time 



optimization. It's similar to what 
some proprietary compilers do. 
It will allow gcc to apply even 
more advanced interprocedural 
optimizations. It's viewing the 
whole program as one object 
rather than source files, so it can 
deduce more complicated infor- 
mation about a program." 

LINK-TIME 

Mark Mitchell, founder and 
chief sorcerer of CodeSourcery, 
is also on the gcc steering com- 
mittee. He said that the gcc has 
changed a lot since he began 
using it in college in the early 
1990s. 

"I think that Richard Hen- 
derson, a developer at Red Hat 
and one of the historically strong 
developers of gcc, was quoted as 
saying, 'We're dragging gcc kick- 
ing and screaming into the 90s.' 
What's funny about it is he said it 
in 2001," said Mitchell. 

"gcc is one of the older appli- 
cations in the GNU Operating 
System," he continued. "The 
world is just so different today. 
The technology for compilers is 
so different, gcc, when I started 
working on it, had many simplis- 



tic assumptions. It really didn't 
look at an entire function and try 
to optimize the whole function at 
once. Building out the infra- 
structure to make it a more mod- 
ern platform has been the focus 
of activity in the last seven or 
eight years. I think at this point 
the internal infrastructure has 
achieved a very strong capability. 
"Against proprietary compil- 
ers, the gcc is increasingly com- 
petitive. The link-time optimiza- 
tion is a new frontier here. One 
of the places proprietary compil- 
ers do outperform gcc is in these 
optimizations. Link- time opti- 
mization is another layer up. It's 
a natural transition up from 
statement by statement, to func- 
tion by function, to file by file, to 
the program as a whole." 

NEW PLUG-INS 

Mitchell said that last month 
the gcc project, for the first 
time, received permission from 
the Free Software Foundation 
to prepare the gcc for plug-ins. 
Previously, the FSF and the gcc 
project had debated whether to 
force plug-ins to adopt the 
GNU General Public License, 



and the final decision bore out 
the FSF's goals. The gcc plug- 
ins will have to use the GPL, 
but Mitchell said that this 
shouldn't be too much of a bur- 
den for developers. 

"It does differ some from 
something like Firefox or 
Eclipse, where the plug-ins can 
be licensed under whatever 
terms," said Mitchell. "Obvious- 
ly, it's consistent with the FSF. I 
don't think it's going to be that 
big of an issue because the goal 
of people who write plug-ins is 
not to make money." 

Some of the first plug-ins to 
surface, said Mitchell, should 
come from universities that are 
already working on ways to 
glimpse the inner workings of 
the gcc during compilation. 

BIG CHANGES 

Ian Lance Taylor, senior staff 
software engineer at Google, has 
been contributing to the gcc pro- 
ject since 1990. He said that, in 
all that time, the biggest change 
he's seen the compiler collection 
undergo was the move to Single 
Static Assignment form in gcc 
4.0, released in 2005. He said 



that the gcc is still relevant in to- 
day's market despite the large 
number of languages and com- 
pilers available. 

"Over time, gcc has become 
the de facto industry standard 
compiler for all non-Windows 
platforms; gcc is available for 
Windows, of course, but it can 
not be called the standard com- 
piler there," said Taylor, "gcc is 
available everywhere, and peo- 
ple have come to expect its fea- 
tures. Providing a high quality 
compiler [that] is generally 
available ensures that all com- 
pilers must meet a minimum 
quality bar, which makes things 
better for all programmers." 

Edelsohn agrees, "gcc is con- 
tinually transforming and rein- 
venting itself. I think that's what's 
made gcc successful," he said. 

Mitchell also sees good things 
for the gcc. "Barring some revo- 
lution in computing that makes 
C and Unix obsolete, I think 
these tools will live on," said 
Mitchell. 

"A few years back, I used to 
have to go and convince compa- 
nies that gcc was relevant. Now 
it's on everyone's plan when 
they're making a new CPU. I 
think gee's got a pretty bright 
future." I 
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Microsoft, SFLC disagree about the GNU GPL 



< continued from page 1 

ware, says Bradley Kuhn, a pol- 
icy analyst and tech director at 
the Software Freedom Law 
Center. The SFLC is not a dis- 
interested party: It is a partner 
with the Free Software Founda- 
tion, which wrote the GPL, and 
sues companies that are 
believed to be violating its copy- 
left requirements. 

"That statement is akin to 
saying that Tndia and China are 
merely two of the 192 (or more) 
countries in the world.'" 
scoffed Kuhn in a direct 
response to Ramji's comments. 

Kuhn estimated that at least 
60% of open-source software 
uses a version of the GPL 



license. "Microsoft is happy to 
take lots and give back a tiny 
fraction. This new message' 
from Microsoft is the same as the 
old one, with some cosmetic 
changes," he said. 

So, why exactly is the GPL a 
challenge to? It's had to know for 
certain what the software giant's 
view is. As for Ramji, he stated, 
"I am personally fairly pragmat- 
ic, so I value things working well 
together — heterogeneous sys- 
tems, hybrid licensing, multiple 
development models. I think the 
GPL is designed toward exclu- 
sivity rather than heterogeneity. 
That produces challenges in how 
we approach it." 

While Microsoft can support 



GPL-based code through its 
partners, as it does with Novell, 
the company can't contribute 
directly to projects due to the 
GPLs license terms and 
requirements, he explained. 

Ramji added that Microsoft 
drafted its Open Specification 
Promise to apply to software 
licensed under the GPL. The 
OSP is a promise by Microsoft 
to not assert its patent rights for 
specific Microsoft technologies. 

Kuhn believes that Microsoft 
is having to have its cake and eat 
it too. 

"The GPL is designed to put 
big corporations like Microsoft 
and individual contributors on 
equal footing," said Kuhn. 



'Microsoft perceives this 
'exclusivity' because it doesn't 
give them the level of incredible 
control over the software to 
which they are accustomed." He 
added that Microsoft has exclu- 
sively favored non-copyleft 
licenses that do not create the 
same "equal footing" situation. 

Despite its present reluc- 
tance to work with the license, 
Microsoft has contributed to 
GPL-licensed software to all par- 
ties' substantial benefit, said 
Kuhn, pointing to Microsoft's 
purchase of Softway Systems, a 
company that produced Unix 
bridging tools that use the GPL. 

"In the late 1990s and early 
2000s, Microsoft was a compli- 



ant distributor (and sometimes 
contributor!) of GPL'd soft- 
ware. [As far as I know], they 
have discontinued the [Unix 
bridging tool] in recent years," 
said Kuhn. He went on to criti- 
cize Microsoft for publicizing 
its non-GPL contributions to 
free and open-source software 
while opting not to draw atten- 
tion to this example. 

"I suppose that's because it 
will draw attention to the fact 
that Microsoft now refuses to 
contribute to gcc and other 
GPL'd software. Obviously, if 
they were to tout that they were 
a previous contributor to gcc, 
they'd have to explain why they 
are not currently," he stated. I 



Eclipse Foundation desires 
Microsoft partnership 

Areas for collaboration: SQL Server, 



BY DAVID WORTHINGTON 

The Eclipse Foundation is look- 
ing for opportunities to work 
more closely with Microsoft, says 
Mike Milinkovich, the founda- 
tion's executive director. Mean- 
while, one observer is skeptical 
about whether a close Microsoft- 
Eclipse partnership would truly 
be a win-win scenario. 

The Eclipse Foundation's 
goal for 2009 is to work with 
Microsoft for opportunities in 
utilizing Eclipse tooling for its 
platforms, said Milinkovich. 

He explained that the majori- 
ty of Eclipse developers target 
Windows, and that Eclipse could 
serve as an onramp to help bring 
developers to Microsoft's plat- 
forms. "It's a win-win for both 
parties," he declared, noting that 
84% of all Eclipse downloads are 
for the Windows platform. 

Microsoft has already thrown 
its support behind a third-party 
project to integrate the Eclipse 
IDE with its Silverlight technol- 
ogy. Milinkovich says that the 
Eclipse Foundation could part- 
ner with Microsoft directly to 
create SQL Server data manipu- 
lation and administration tools, 
as well as on projects related to 
service-oriented architecture 
and modeling. 

Eclipse's software modeling 
framework can be made inter- 
operable with Microsoft's M 



modeling language by leverag- 
ing the XML Metadata Inter- 
change model interchange lan- 
guage, he noted. 

The foundation is talking to 
the appropriate technical lead- 
ers at Microsoft, but it has not 
received any commitment yet, 
Milinkovich said. "Working 
with Microsoft is like wildcat oil 
drilling: You hit a lot of dry 
wells, but there is a good one 
once in a while. Microsoft is 
very approachable, and it is 
making decisions for business 
reasons, as it should be." 

Tony Wasserman, a professor 
of software management prac- 
tice and executive director at the 
Center for Open Source Investi- 
gation at Carnegie Mellon Sili- 
con Valley, said, "In thinking 
about possible relationships 
between Microsoft and the 
Eclipse Foundation, it would 
make sense for the two groups 
to collaborate in those areas 
where benefits would accrue to 
their respective users." 

A Microsoft-Eclipse partner- 
ship must work on a business, 
technical and personal level if it 
is likely to succeed, Wasserman 
said. He added that while the 
"win" for Microsoft is clear, he is 
less sure on what the "win" is for 
the Eclipse Foundation, other 
than having Microsoft join as a 
strategic member and contribut- 




Collaboration makes sense, says 
Carnegie-Mellon's Wasserman. 

ing up to US$500,000 per year. 

"Given the current makeup 
of the Board of the Eclipse 
Foundation, I'm not sure how 
such a membership application 
would be received," he said. 
Microsoft did not return com- 
ment by press time when asked 
about whether it intended to join 
the Eclipse Foundation board. 

Eclipse developers paid by 
their employers to work on 
Eclipse-related projects proba- 
bly wouldn't care, said Wasser- 
man. However, enthusiasts 
might be unhappy, he noted. "A 
typical unpaid volunteer con- 
tributor to an Eclipse project 
might be less likely to work on 
the project if he (or she) felt 
that his or her work was going 
to benefit a large for-profit 
business such as Microsoft." I 



Hard times hit 
tech giants 



< continued from page 1 

profitable, its stock's earnings 
per share was 47 cents, com- 
pared to a guidance of 51 to 53 
cents. Revenues fell short by 
approximately $1 billion. 

Much of the decline was 
experienced in Windows client 
revenue, a cash cow for the com- 
pany. That revenue fell 8% "as a 
result of PC market weakness 
and a continued shift to lower- 
priced netbooks," the company 
stated in its annual report. 

Weak PC sales have also 
affected chipmakers AMD and 
Intel. Semiconductor sales fell 
to $20.8 billion in 2008 from 
$23.1 billion in 2007, according 
to a recent report by the Semi- 
conductor Industry Association. 

On Jan. 16, AMD announced 
plans to reduce its workforce by 
nearly 9%. It will also cut 
employee compensation during 
its first quarter. 

AMD's top executives are 
taking a hit to their base salaries, 
and other employees will see 
their incomes drop on a stag- 
gered basis depending on their 
employment status. Other bene- 
fits, including the company's 
401(k) matching program, are 
suspended indefinitely. 

"These actions, while diffi- 
cult, will allow AMD to better 
navigate the turbulent econom- 
ic conditions while protecting 
our core capability to execute 
our technology road maps and 
position AMD for long-term 



success," said spokesperson 
Michael Silverman. 

In the fourth quarter of 
2008, AMD reported a net loss 
of $1,424 billion, or $2.34 per 
share. For continuing opera- 
tions, fourth-quarter 2008 net 
loss was $1,414 billion, or $2.32 
per share, and operating loss 
was $1,274 billion. 

At present, AMD has about 
15,000 employees. Three thou- 
sand are set to be transferred to 
the Foundry Company, a spinoff 
dedicated to building foundries. 

Intel announced that it 
would also be consolidating 
manufacturing operations by 
closing down some of its older 
factories. The facilities are 
located in California, Oregon, 
Malaysia and the Philippines. 
Between 5,000 and 6,000 jobs 
will be cut, said corporate 
spokesperson Chuck Mulloy. 
Intel has around 84,000 
employees worldwide. 

"We are investing in new 
products and leading-edge man- 
ufacturing," Mulloy said, adding 
that the closures would not 
affect its transition to a 32nm 
chip fabrication process. Older 
facilities were already scheduled 
to be "taken out," but that the 
downturn accelerated the com- 
pany's plans for those closures. 

Intel started the year with 
nearly $14 billion in cash, he 
said, adding, "We are a capital- 
intensive business and must 
keep cash flow positive." I 
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Nexus Pro addresses enterprise repository woes 



BY ALEX HANDY 

For Maven wizards, the tough- 
est part of daily life can be the 
analog processes surrounding 
development teams. Sonatype, 
the company founded by Maven 
creator Jason van Zyl, is now 



offering Nexus Professional, a 
beefed up version of its Maven 
repository manager that now 
includes options to help 
enforce life-cycle and legal 
rules within binary storage sys- 
tems. Nexus Professional is 



available for US$2,995 per year. 
Brian Fox, vice president of 
engineering at Sonatype, said 
that the biggest distinction 
between the open-source ver- 
sion of Nexus and the commer- 
cial Professional version is the 



addition of LDAP support. 
Thus, Nexus Professional can 
now authenticate users through 
Active Directory. 

Another Professional feature 
is automatic staging and promo- 
tions. "One of the things that's 
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important to do is to be testing 
and QA'ing the artifacts that 
come out of your build," said 
Fox. "It's not sufficient to QA 
snapshots and later on produce 
and release a build. 

"Previously, there was no 
good way to share these binary 
artifacts for a release. Nexus 
allows you to deploy these arti- 
facts, and it will create a tempo- 
rary staging repository for the 
person who's doing a build. It 
will hold them there until they 
are promoted to the release 
repository," he said. 

That means whole stacks of 
software related to a single pro- 
ject can be stored in their very 
own automatically created 
repository. This ensures no mix- 
ups when it comes time to 
deploy, as the unfinished soft- 
ware is quarantined in its own 
repository until a manager 
deems it worthy of promotion. 
Automatic staging is a new 
capability for Nexus Profession- 
al; in the open-source Nexus, it 
must be done manually 

Fox said that staging and pro- 
motion is a big challenge: "A lot 
of people were doing it by hand 
before. It required a lot of man- 
ual intervention. Then there's 
the Maven metadata and the 
hashes that needed to be updat- 
ed. Now all components get pro- 
moted as a single unit." 

LAWYERS IN THE REPOSITORY 

Another area for Nexus Profes- 
sional is compliance. "Organiza- 
tions aware of the legal ramifica- 
tions of open source are often 
set up so that the developers 
can't use open source without 
prior approval. Often they have 
a manual setup," said Fox. 
"They'll set up a hosted reposi- 
tory that's not connected to the 
outside world. When a develop- 
er wants something, they have to 
request it. It's a heavy workflow. 
It's prone to errors. 

"So the procurement support 
automates that [with] a special 
type of repository, which is a 
proxy repository. It acts sort of 
like a firewall. If artifacts are not 
explicitly allowed, they are 
implicitly denied. Your release 
builds would operate against this 
procurement repository." 

Options allow development 
teams to flag entire open-source 
projects as safe, allowing any 
version to be pulled down 
through the repository rather 
than having to flag each one as a 
separate approved artifact. I 
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GNU is Not Unix, but it is 25 

A generation of developers has been influenced by the free software movement 




BY ALEX HANDY 

In the earliest days of computers, just 
about everything could be considered 
free software. Computers were so large, 
unwieldy and difficult to understand 
that any reasonably well-written pro- 
gram would be passed around via punch 
cards or paper tape. Into 
that free software world 
Richard Stallman was born. 

In the 1960s, he pro- 
grammed IBM System/360 
mainframes in PL/I, a proce- 
dural language that itself is 
celebrating its 45th anniver- 
sary this year. In the 1970s, 
Stallman worked at the 
famous MIT Artificial Intel- 
ligence laboratory. Along the In the 25 years since 
way, he saw software devel- Richard Stallman began 
opers change their attitudes work on the GNU operating 
and move away from open- system, much has changed. 
ness toward the proprietary. 
It was this shift in the hacker culture, as 
he called it, that eventually led him to 
strike out on his own in 1983. 

"In the 70s, operating systems mostly 
became proprietary," said Stallman. "I 
was working in a sort of island where a 
more ethical and cooperative way of life 
still existed; namely the AI lab at MIT. 
We had an OS that was entirely free soft- 
ware. But then that community died in 
the early 80s." 

During that time, a company called 
Symbolics built proprietary LISP sys- 
tems, combining both hardware and 
software. Stallman saw this closed- 
source approach as the antithesis to his 
desires for free software. 

"I spent a couple of years punishing 
Symbolics by attacking it and giving an 
ultimatum to the people at the AI lab," 
he said. "I didn't want to spend the rest 
of my life punishing somebody. I wanted 
to rebuild what was destroyed. I wanted 
to be able to use computers while having 
freedom. This is impossible if you have a 
proprietary program." 

So Stallman spent most of 1984 writ- 
ing a free operating system. He named 
this body of work with a recursive 
acronym: GNU, meaning GNU is Not 



Unix. He began by modifying a compil- 
er called Pastel, but soon found it lack- 
ing and rewrote it from scratch; this lat- 
er became the foundation of the GNU 
Compiler Collection, or the gcc. Next, 
he reworked the Gosling Emacs text 
editor, eventually replacing all of its 
code with LISP. This would 
become Stallman's first 
piece of free software: 
GNU Emacs. 

The rest, as they say, is 
history. To release GNU 
Emacs, Stallman needed a 
license. While his initial 
license, released in 1985, 
wasn't the GPL, it was his 
first step into the world of 
legal wrangling. Four years 
later, that license, and other 
GNU licenses, merged into a 
single form: the GNU Gen- 
eral Public License. 



THE GPL: STILL RELEVANT 

Twenty years after the release of the first 
GPL, it is hard to deny the license's 
influence and prominence. It's believed 
that over half of the world's free and 
open-source software is available under 
the GPL or a variant. 

James Grimmelmann, professor at 
the New York Law School, said that the 
GPLs biggest strengths are its public 
scrutiny and broad adoption. 

"It is an especially well-drafted 
license," he said. "There are many licens- 
es. Many of them are well drafted. But 
the GPL, especially through community 
effort, has received an extremely close 
level of reading over the years. They've 
thought of a lot of contingencies." 

Twenty years on, the GPL still hasn't 
seen the inside of a courtroom. But 
Grimmelmann said that this is still not a 
hindrance to it. In fact, aside from some 
remaining quibbles over GPLv3's han- 
dling of digital rights management, and 
some legal questions on whether it is a 
license or contract, there is little contro- 
versy remaining around the GPL. 

"It's almost impossible to invalidate the 
GPL without invalidating most open- 



source licenses," said Grimmelmann. 

But that's not likely to happen any 
time soon, he added. "Most contracts 
and licenses are never litigated, and we 
don't worry about that fact. The indica- 
tor of a successful legal document is if it 
never winds up in court. Imagine a con- 
tract to purchase 10 tons of steel. When 
you see those in court, you don't worry 
that the steel industry is going to col- 
lapse," he said. 

But would the GPL (and the GNU 
Project and the Free Software Founda- 
tion) collapse without Richard Stallman? 
What happens when Stallman retires? 
Brett Smith, FSF license compliance 
engineer, said that the FSF has long been 
decoupled from Stallman, thanks to its 
non-profit status. "The FSF as an organi- 
zation is a steward for the license and, 
organizationally, we have a board of 
directors who are responsible for the 
well-being of the foundation," said Smith. 

GNU/LINUX OR JUST LINUX? 

A constant area of strife within the GNU 
community revolves around Stallman 
and his rigorous semantic debates. Brian 
Behlendorf, a founding member of the 
Apache Foundation, thought Stallman's 
insistence on specific nomenclature, and 
his lack of tolerance for other opinions, 
was distracting. 

Behlendorf uses the term "Open 
Source" interchangeably with the term 
"Free Software," something Stallman 
vehemently opposes. Behlendorf takes a 
broader view of the free software ecosys- 
tem and sees room for many variations on 
the GPL theme, even ones that do not 
compel redistribution of derivative works. 

"A lot of the world has moved on from 
license differences," said Behlendorf. "It 
used to be the case in the 1980s that the 
idea of giving away software that wasn't 
shareware that you got the source code to 
was novel. Compelling the giveback was 
the only way to go. There was the Berke- 
ley license, but because there wasn't give- 
back, the industry was fragmented. That's 
why the original Unix marketplace failed. 
In the early days of the Free Software 
Foundation, they had to have that 



BIRTHDAY TIDINGS FOR THE GNU GENERAL PUBLIC LICENSE 



25 YEARS OF 


FREE SOFTWARE 


ifcJ--»i 


Richard Stallman is born in New 
York City. 


™ 


Stallman graduates from Harvard 
with a BA in Physics. In the fall, 
he enrolls at MIT. 


WkVA 


Stallman works to recreate the 
work of Symbolics, attempting to 
make free what he saw as 
proprietary software. 


[221 stallman begins work on what would 
become the GNU operating system. 


WkTA 


Stallman writes a number of tools, 
including the beginnings of the gcc 
and Emacs. 


IfcMJ 


Emacs is completed, and Stallman 
releases it for Unix. He also writes 
the GNU manifesto. 


ifciifri Work begins on the GNU Debugger. 


E3 


gcc 1.0 is released under its 
own license. 


IHA1 


Roland McGrath completes initial 
work on the GNU C Library. 


IEEH 


Stallman writes the GPL. 


IHJJ 


John Gilmore becomes maintainer 
for the GNU Debugger. 


IHJI 


Linus Torvalds begins work on the 
Linux kernel. He releases it under 
the GPL a year later. 


FEEE1 


gcc 2.0 is released. 


Ea 


EGCS is created to bring together 
some experimental forks of the gcc. 


n=ni 


EGCS and the gcc are merged. 


M»MI 


gcc 3.0 is released. 


WI»M 


GPL 3.0 is released. 



because the benefits were not obvious." 

"I do think free software and open 
source have a symbiotic relationship. If 
Stallman hadn't existed, we would have 
had to invent him. It's necessary to have 
the advocates and [to have] them not 
compromising in order for the rest of us 
to help bring the world along," he said. 
He concluded that thanks to the GNU 
Project and Stallman, "We have a whole 
generation of software developers for 
whom that has become second nature." I 



Mark Shuttleworth 

CEO and founder of Canonical 
Future generations will come to 
depend heavily on a vast body of 
code and content that empowers all, 
and yet is rigorously defensible in 

J. legal terms. The GPL was the pio- 
I neering effort that established the 
I principles that underlie much of 
*™""™ today's open and collaborative licens- 
ing: harnessing the global copyright system to establish 
a formal basis for copyleft and share-alike content. [The 
FSF] remains at the forefront of copyleft code licensing. 




Simon Phipps 

Chief Open Source Officer, Sun Microsystems 
Twenty-five years ago was a time of 
change for the computer industry, just 
like today. The major vendor was 
wrestling with anti-trust suits. Disrup- 
tive technologies were taking the mar- 
■ ket beyond the incumbent hardware. 
Richard Stallman's creation is just as 
fresh and relevant (and disruptive) 
[today] as it was then. The GPL, and the commons it cre- 
ates, are still playing a crucial role creating the freedoms 
we need for our future. 




Mike Milinkovich 

Executive director of the Eclipse Foundation 
The Free Software Foundation and 
specifically Richard Stallman deserve 
a lot of credit for being the pioneers 
that created the GPL. The Free Soft- 
ware movement has been a critical 
catalyst for change across the entire 
1 [I software industry. Looking forward, I 
m« believe licenses like the Eclipse Public 
License and the Apache Software License tend to be 
more inclusive of different philosophies of open-source 
participation and a wider variety of business models. I 
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Li the eyes of Mike Weider, the 
correct way of doing software security 
testing requires getting into the mind of 
the hacker. 

The director of security products for 
IBM Rational said it takes a special 
breed of software professional to step 
into the driver's seat of a hacker's men- 
tality and take the wheel. While quality 
assurance professionals can do security 
testing and smoke out some vulnerabili- 
ties, they usually have the customers' 
thoughts in mind rather than those of 
the hacker. 

"There is a need for this specialized 
security testing professional to antici- 
pate how hackers think and use this 
slightly different way to test applica- 
tions," Weider said. 

From a technology standpoint, there 
are two main approaches for testing soft- 
ware for security, and they are well 
known to developers and testers. One is 
exercising the software from what many 



the tester will be worried about someone 
trying to tamper with the logic," 
DeMarines said. "If we're talking about a 
piracy threat to a publisher, someone 
who is issuing software as part of their 
business, there are some ways you can go 
out and take a look at how those attacks 
are carried out, and then look at ways to 
bolster your defense against that. The 
first step is understanding how the 
attackers are going to look at the applica- 
tion and the methods they're going to 
use to go after the vulnerabilities." 

Depending on what the threat is, 
organizations can either use their own 
resources or outsource for analysis to 
carry out this form of testing, 
DeMarines said. The ability to use an 
outside resource to test for threats 
depends on the amount of money an 
organization has. 

Jacob West, manager of Fortify Soft- 
ware's security research group, said the 
most important thing in assessing the 




call the outside-in approach: testing to 
see how the application responds to a 
simulated attack. The second is more of 
an inside-out approach, which looks for 
coding patterns that would highlight vul- 
nerabilities in the code. 

But security testing can be fundamen- 
tally a different ballgame than traditional 
testing because the emphasis is put on 
what an application should not do rather 
than what it should do. First, users don't 
usually try to search out software bugs, 
while malicious attackers intentionally 
seek out vulnerabilities. When vulnera- 
bilities are found by hackers, problems 
arise for other users instead of just a 
developer or group of developers. 

Additionally, developers usually learn 
to avoid poor programming practices for 
their own projects, but it is difficult for 
security testers to keep up with the lat- 
est exploits because they grow every 
year. This makes it more difficult to 
ensure that secure programming prac- 
tices are followed. 

So what is the best way to carry out 
proper security testing? Vic DeMarines, 
vice president of products at security tool 
maker Vi Labs, shared Weider's notion 
that testers need to think like the attack- 
ers themselves and to look for the easiest 
way to initiate a threat. Applications will 
have different levels of threats, depend- 
ing on the nature of the application. 

"If we're talking about a financial 
application that's running in a hosted 
environment, and it's a Web application, 



security of software is to ask what can go 
wrong. That underpins any security test- 
ing activity because it puts the focus on 
things the software is not supposed to do 
instead of things it's supposed to do. 

"The challenges for security testers 
are going to be very similar to the chal- 
lenges that developers went through as 
software security became a part of soft- 
ware development," West said. "Early 
on, we had developers saying security 
isn't their problem, that's what the secu- 
rity team does, and slowly we've con- 
vinced programmers that security is part 
of the development process. 

"The same evolution is going to hap- 
pen in the security testing space. People 
who have thought of themselves as 
doing traditional quality assurance are 
going to have to think of security as part 
of their approach. As such, they'll start 
to build up some knowledge of security 
and the kinds of things that can go 
wrong in specific circumstances." 

Gwyn Fisher, CTO of Klocwork, 
another security tool maker, said the 
whole issue with security is that a tester 
should not intend to find out if the soft- 
ware is secure at the end of the process. 
Instead, security testing must involve 
everyone; the architect should test his or 
her design assumptions for vulnerabilities, 
the coder should be responsible for test- 
ing what is being produced, and so forth. 

"You get a secure product by follow- 
ing a secure development life cycle. You 
don't get it by testing," Fisher said. "It's 




all about the notion of software security 
not coming from the outside in; it comes 
from the inside out." 

ADDING SECURITY TO THE CYCLE 

There is a great deal of talk in the software 
industry about making sure security is 
instilled throughout the software develop- 
ment life cycle, but there is no guarantee 
that such talk translates to action. Howev- 
er, Weider said IBM Rational has seen "an 
evolutionary approach," where the securi- 
ty team looks to improve the security of 
the applications at the beginning of the 
development process. 

"That works well to begin with, to 
have sort of a gatekeeper, but that also 
has the potential to become a bottleneck 
in that there're very few security people, 
but there are hundreds or thousands of 
developers," Weider said. "With the 
movement to agile approaches [that 
have] many smaller iterations, having 



that testing at the end of the process 
doesn't make as much sense as having it 
embedded throughout the process." 

An agile process caters well to the idea 
of implementing security throughout the 
development life cycle because the con- 
cept calls for testing in each iteration, 
Weider explained. In the past, security 
testing has been something done last 
minute, and it was typical for testers to 
find a glaring vulnerability that would take 
weeks or a month to fix. The tester would 
then be left with the sticky situation of 
either delaying the release to fix the vul- 
nerability, or looking the other way and 
letting the application go live with known 
bugs. Because of that, Weider said, there 
has been a push to integrate security test- 
ing into earlier phases of development. 

One of the things IBM Rational is try- 
ing to do is to integrate security within 
development tools in such a way that it 
becomes a part of how an application is 
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defining the proper security require- 
ments is not always easy because they 
might be seen as redundant or difficult 
to comprehend for other professionals 
on a project. Some security require- 
ments do come in the same form as tra- 
ditional software requirements, speci- 
fying positive security features, such as 
a particular encryption algorithm the 
software should use, or making sure 
user accounts are disabled after three 
unsuccessful login attempts. 

In security requirements, there is a 
much greater emphasis on negative 
requirements, where testing revolves 
around statements like, "Outside 
attackers should not be able to modify 
the contents of the Web page," or, 
"Unauthorized users should not be able 
to access data." This will have a big 
effect on how testing is carried out. 
Testing positive requirements involves 
creating conditions that will verify that 
the requirement is satisfied by the soft- 
ware. On the other hand, negative 
requirements can state that something 
should never occur, which would 
involve creating every possible set of 
conditions to determine that it won't 



be a challenge because there will 
always be a risk of turning a vulnerabil- 
ity around into a negative requirement 
that isn't constructive for the down- 
stream testers, because it's not verifi- 
able in some way." 

West added that testers need to go to 
a lower level of granularity and turn 
vague requirements into smaller, more 
actionable ones. Testers should point out 
specific potential vulnerabilities, like 
stating that there is a possibility of a com- 
mand injection vulnerability because 
shell scripts are running on the back end. 
In that case, the proper requirement 
might say, "No user input should be 
allowed to appear in a shell command 
that's executed." 

IBM Rational's Weider said that 
articulating security requirements can 
be difficult, and rarely are there people 
with the right skills to define what the 
requirements should be. He emphasized 
the importance of security in the design 
of applications, and said it is important 
to integrate threat modeling and other 
types of threat analysis into the design 
process to ensure that security is cap- 
tured in the design and architecture. 
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built, rather than something that's bolted 
on after the software is developed. 

Vi Labs' DeMarines agreed that secu- 
rity needs to be kept in mind throughout 
the development process. In terms of 
thinking about the next release as an 
application is under construction, a 
tester has the chance to figure out how to 
make it more resistant to tampering or 
piracy during the design phase. Testers 
can use tools that hackers might use to 
analyze or reverse-engineer an applica- 
tion. This can give the tester a better 
sense of how sturdy the application is. 

"You don't want to be starting to think 
about testing security as you're coming 
into a release candidate," DeMarines 
said. "You want to be looking at this fair- 
ly upfront when most of the functionality 
has been implemented in a way that you 
can test it, and then figure out how to 
make it resistant to the kinds of threats 
the enterprise is worried about." 



While there are many products on 
the market that allow software providers 
to scan source code for vulnerabilities, 
and it is important to do so, the key is 
acquiring the mentality to understand 
what the threat is and putting that feed- 
back into the design, DeMarines added. 

West said that mentality is pretty 
well ingrained in most developers 
today, and the enterprise software 
industry has realized that security 
needs to be a part of the full process. 
"There's still a wide range of maturity 
levels in terms of how close companies 
are getting to obtaining that Utopia of 
software being built in at every step, 
but for the most part, companies are 
doing whatever they're able to now in 
order to make that a reality," he said. 

POSITIVE VS. NEGATIVE 

When attempting to implement securi- 
ty throughout the development process, 



Industry figures say proper 
testing for security requires thinking 
like an attacker, instilling security 
into the full development process 



occur, which is close to impossible. 

Most relevant requirements aren't 
going to be positive, said West. Some 
will be redundant because they will tell 
the tester to avoid obvious vulnerabili- 
ties. A requirement like, "An attacker 
should never be able to take control of 
an application," is the type of require- 
ment that should be moved away from 
because it isn't particularly useful. Good 
security requirements can give clues to 
testers downstream about what might 
constitute unintended behavior. 

"You could say, for example, the 
application will never render un- 
encoded HTML or Javascript," said 
Fortify s West. "That's something a QA 
tester with relatively little security 
knowledge could go into a specific test 
case and verify. They can submit 
HTML characters to that page, and 
when it is displayed back to me, there 
shouldn't be any shown. That's going to 



Additionally, it's not always easy to 
have all requirements accepted because 
there can be many more requirements 
than can fit into a given cycle, Weider 
said. This results in a "tug of war" as far 
as what requirements make it into the 
process. Because of this, testers need to 
prioritize security improvements to the 
application in the same way other soft- 
ware professionals prioritize quality and 
functional improvements. 

"That is the challenge, but I think 
every year it's getting a little better as 
security is becoming more accepted 
within development," Weider said. "In 
the past, it wasn't something that was 
well understood, but now as we've seen 
application security becoming one of 
the main vulnerabilities on the Internet 
as well as compliance issues, the priori- 
ty of security in development require- 
ments has been getting steadily better 
every year." I 
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FROM THE EDITORS 

What's GNU? 25 years! 

Its been about a quarter of a century since Richard Stallman and the 
Free Software Foundation unveiled two important milestones in the 
open-source movement: the GNU Project and the Free Software Foun- 
dation. From them came very important projects like Emacs, the GNU 
Operating System, the GNU General Public License and the GNU 
Compiler Collection. 

Whether you like or dislike Linux (which was built using GNU tools), 
or whether you admire or revile the GPL, there's no doubt that the Free 
Software Foundation has had a profoundly significant impact on nearly 
every aspect of software development. Yes, Stallman is a polarizing fig- 
ure. Yet when you look back at his track records, from Emacs to the GPL, 
from the gcc to Linux, his work has touched us all. 

That's not to say that everything about the Free Software Founda- 
tion and Stallman (it's almost impossible to separate the two) is 
admirable. Stallman's long-standing grudge against Linus Torvalds 
gets in the way. So too does Stallman's habit of insisting that reporters 
refer to Linux as GNU/Linux. Sorry, rms, that battle has been lost. It's 
time to move on. 

Hmm. Do you think that Stallman will move on? Of course not. That's 
not in his nature. He's a never-give-up, never-surrender fighter and has 
been since he began writing his license and operating system. Nomen- 
clature notwithstanding, he and the FSF have been remarkably success- 
ful in creating both software and licenses that have profoundly influ- 
enced both open-source and commercial development. 

Since the advent of GPLv3, however, the question is now, "Where 
does the Free Software Foundation go from here?" For better or worse, 
the organization's latest battles haven't been technological, but legal. 
Stallman, the FSF and its partner, the Software Freedom Law Center, 
are now focusing on corporate compliance with their licenses. They're 
not innovating, they're litigating. 

Yes, a license without compliance is valueless. Yet we'd rather that the 
standard-bearers of the open-source movement return to their tradition- 
al role of winning hearts and minds. We'd rather they talk to developers 
instead of attorneys. 

It is not clear to us what Stallman and the FSF intend to do next to 
build upon their success. We're sure that there's going to be a lot more 
to come. Born in 1953, Stallman has many fruitful years of activism, 
compiler optimization, complaining about Linux and license rewriting 
ahead of him. Let's hope that the next 25 years are famous for more 
creativity along the lines of Emacs and the gcc, not an endless stream 
of GPL lawsuits. 



Tightening belts 



Microsoft, Intel, AMD: They're among the companies laying off 
employees in the face of today's economic slowdown. Call it a 
recession, call it whatever you want, but organizations large and small are 
tightening their belts and reducing their payroll. 

On the grand scale, the layoffs in the technology sector are small. 
Sure, that's no consolation to those who have been laid off, and we 
empathize with everyone who has lost a job or seen a reduction in pay, 
hours or benefits. Still, we must acknowledge that the tech industry is 
faring better off than other industries. Around the same time that 
Microsoft, Intel and AMD announced their cuts, heavy construction 
equipment maker Caterpillar slashed 20,000 jobs. 

The good news is that, long term, the prognosis for our industry is 
strong. Software developers and development managers are valuable 
employees. Yes, anyone is obviously vulnerable when companies go out 
of business or institute massive layoffs, and yes, it can take some time to 
find a new position. Yet we believe that when the economy recovers, 
organizations will set a priority to rebuild their battered software devel- 
opment teams. I 



What's so scary about 
a featureless future? 



For decades, most software compa- 
nies have taken a specific approach 
to creating new versions of their prod- 
ucts: Pile on additional features, market 
them as the newest and greatest, then sit 
back and hope the revenue 
comes pouring in. 

In the best case, before 
starting development, the 
vendor surveys users to find 
out which features top their 
wish lists. In other cases, the 
approach can be a casual one: 
getting a few sales people into 
the office and asking, "So what 
do these people want?" And, 
of course, there's the "devel- 
oper knows best" approach, which 
bypasses any polling or information- 
gathering in deference to the develop- 
er's superior knowledge of what makes a 
product great. 

Once the feature list is prioritized, 
developers go to work ladling these new 
features into the software framework, 
trying to fit in as much as possible with- 
in the promised delivery time. If they 
can't deliver a feature list that looks good 
on a spec sheet, website and press 
release, they might delay delivery or 
compromise on a reduced feature set 
that will stem the tide until the next 
product release. 

If users get what they think they 
requested, and the features actually do 
what they are purported to do, then 
this feature -driven approach works 
fine. Users can justify upgrade pur- 
chases to their bosses based on waving 
the spec sheet and reiterating the ven- 
dor's promises of better performance 
and quality. 

From the vendor side, it works won- 
derfully. A new version of software 
with additional features typically opens 
up a fresh revenue stream, giving an 
existing product new life and making a 
substantial contribution to the vendor's 
bottom line. 

So, if the user is happy and the ven- 
dor is happy, what's the issue? 

The issue is one of missed opportuni- 
ty: the opportunity to do something that 
users have never seen before and could 
never even imagine, much less request 
in a feature survey or discussion. It's 
something that gets a job done in a way 
that makes their lives better. 

Developing this type of product 
requires going beyond features. It 
means concentrating on what the cus- 
tomer wants to achieve. Sounds simple, 
but it is extremely difficult. The rewards 
for getting it right, however, are much 
greater. 

Take a look at the search engine mar- 



Simon Galbraith 




ket just before the turn of the century. 
Alta Vista, Hotbot and Infoseek were 
doing a pretty good job with their search 
engines, and people were relatively hap- 
py to use them. You didn't hear a lot of 
cries from the general public 
for a simpler, more effective 
search engine. Then came 
Google. 

A couple of smart guys 
from Stanford figured out 
that all people cared about 
was the fastest, simplest, 
best way to search. They 
developed a product that 
does one thing awesomely 
well. By concentrating on 
the end result — better search — and pio- 
neering new ways to get there, Google 
changed the whole landscape and creat- 
ed a brand name that's both a noun and 
a verb. 

Conventional wisdom says that you 
can't sell a product without promoting 
new features. The rationale is that cus- 
tomers talk the simplicity talk, but they 
buy based on the feature list. 

It's true that there will always be 
people who want more features, just as 
there are people who want to wear 
multiple gold chains or buy the car 
with the most options. But I like to 
think that software professionals are a 
different breed. They know their jobs 
well enough to recognize a tool that 
can save them time and energy. They'll 
settle for new features and incremental 
improvements if that's what you got, 
but they'll devour anything that ele- 
gantly solves a problem in a simple 
way, even if it doesn't come with a 
page-long feature list. 

The key is getting potential cus- 
tomers to try the product. That's where 
providing free trials of the complete 
software over an ample amount of time 
makes the difference. Many companies 
don't do this for fear of piracy, or that 
the software will be used to take care of 
a problem during the evaluation period 
and not be purchased. But these are 
chances a vendor should be willing to 
take. 

Once someone has a chance to try 
something that works better and more 
simply, evidence shows that not only will 
they buy in a big way, they will also 
become advocates for the company that 
solved their problem. That's what sepa- 
rates what Steve Jobs calls the "insanely 
great" product from the merely compe- 
tent one. I 

Simon Galbraith is joint CEO of Red 
Gate Software, which makes tools for 
SQL databases and .NET developers. 
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LETTERS TO THE EDITOR 

A misunderstood science 



In regards to Zeichick's Take ("Reboot- 
ing Computer Science," sdtimes.com 
/link/33201), I think that Computer 
Science has always been misunder- 
stood. When I was in college in the late 
1970s, Lehigh University had a Com- 
puter Engineering degree but no Com- 
puter Science until my last year there. 
Via the rumor mill, I understood the 
reason was that three departments 
wanted it to be part of their depart- 
ment: Math, Philosophy and Electrical 
Engineering (Computer Engineering). 
EE has changed to Electrical and 
Computer Engineering, and now 
includes Computer Science. 

Another thing about Computer Sci- 
ence is that what you learn today is 
almost always outdated the next year. 
And depending on what a person is 
interested in, there are so many areas 
to explore. Only some of these areas 
lead to real jobs. There are only so 
many compiler designing jobs around. 

Companies also need to be more 
involved with the college community 
and to inform them of what the compa- 
ny is really looking for when they're 
hiring new grads. Although, I think 
neither the ones doing the hiring nor 
HR really know what they need. What 
good is a Computer Science degree if 
you can't get a job? 

I have taken some courses at my 
local technical college. From my expe- 
rience with the programming courses, 
I would never hire a graduate of 
my college for a programming job, 
because they really didn't do any 
actual programming in the courses I 
took. One thing that might be of use to 
those wanting to learn more about 



what they can do with Computer Sci- 
ence is what Lehigh had for their engi- 
neering students. 

The first engineering course was a 
programming course, with a weekly lab 
that included a visitor from one of the 
Engineering departments to explain 
what his or her field of engineering 
could do. Sometimes we even visited 
the classrooms for those departments. 
Because everyone needs to understand 
computer technology, this idea could 
be part of an "intro to computers" 
course that is required for all students. 
Also, there may be a way of relating 
some courses within other majors that 
require some Computer Science 
understanding, such as how to really 
make use of MS Access (with advanced 
VBA programming), or advanced 
Macro programming for MS Excel. 

My degree is in Computer Engi- 
neering. I had a hard time fitting into 
the IT mold when all the computer 
programming was plugged into IT. My 
first jobs were in the electrical engi- 
neering departments. It was kind of 
interesting because the old-time EEs 
had a hard time understanding where 
computers fit (in the early 1980s). But 
there is only so much you could do 
with electronic relays. 

Charlene Wroblewski 

WebWise Wardens 

THE FIRST SOLUTION 

I think that the computer science 
world should take a page from Dean 
Kaman's FIRST, although I'm not 
exactly sure where to start. FIRST is a 
program that starts in the lower grades 
with the Jr. FIRST Lego League, and it 



Open-source projects 
deploy on the cloud 

Of those who plan to use the cloud: 

28% plan to use Google's App Engine. 
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15% plan to use Amazon's services. 



9% 

plan to use 
Microsoft's services. 



9% plan to use IBM's Blue Cloud. 



1.5% plan to use 

Salesforce.com's 
Force.com 



Many developers working on open-source projects intend to provide their applications as 
Web services through commercial cloud providers, according to a survey from Evans Data. 
The survey talked to over 360 developers involved with open-source development and was 
conducted in November 2008. 

Source: Evans Data Open Source Development Survey 



runs all the way to the FRC (FIRST 
Robotics Competition). 

Again, I don't know exactly where to 
start with computer science, but FIRST 
makes engineering fun. One aspect of the 
program that I find interesting is that it 
relies heavily on mentors, adults who 
contribute knowledge and who guide the 
students that are involved. FIRST is very 
hands-on, even for the adults, and the 
participating students get to see a multi- 
discipline approach to engineering a solu- 
tion in action. The competition is intense 
and compressed into a rather short peri- 
od of time, but the game and the kit pro- 
vided give the opportunity to succeed. 

Back to computer science, it would 
be great to create some form of compe- 
tition that would introduce children to 
"computing" at an early age and increase 
the scope of the competition as they 
grow older, without presenting an insur- 
mountable challenge. It is essential that 
it involve adult mentors, as that is an 
invaluable transfer of knowledge. I am at 
a loss as to where to start, but I might 
come up with some ideas. I have some 
kids that I need to ask... 

Randy Zeitvoqel 

Beverly Hills, MI 

GETTING THE GIRLS INVOLVED, TOO 

It's clear that the Rebooting Summit 
group identified the issues well. There 
are many groups around the country 
who are taking action and demonstrating 
positive results. The challenge is taking 
these tactics that are known to work and 
leveraging them on a broader scale. 

I am part of an organization focused 
on getting more girls into computer 
careers: the Michigan Council of 
Women in Technology Foundation 
(mcwtf.org). We have learned that you 
can inspire girls by showing them they 
CAN DO IT (letting them get hands on 
technology); showing them that it's fun 
(letting them build computer games and 
robots); showing them the social rele- 
vance (learning what the CIO of Leader 
Dogs for the Blind does, for example); 
and doing it all with their peers (so it's 
cool). You get them hooked for life! 

We do this with summer camps and 
robotics for middle schoolers, and clubs 
with various activities for high school 
girls. There are other programs like this 
that have demonstrated the same posi- 
tive results. The challenge is to go 
national: connect them up or leverage 
them in a repeatable way. 

Rosemary Bayer 

Michigan Council of Women in 

Technology Foundation 

WHAT DO YOU THINK? 

SD Times welcomes feedback. Letters 
should include the writer's name, com- 
pany affiliation and contact informa- 
tion. Letters become the property of 
BZ Media and may be edited for space 
and style. Send your thoughts to 
feedback@bzmedia.com. 
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When 100% code coverage is not enough 



In my previous discussions of code 
coverage, I explained the reasons 
why 100% code coverage from tests is 
not a desirable goal. To recap, there 
is a lot of code that does not need 
to be tested, and writing code specifi- 
cally to test it is simply a waste of time. 
For example, testing setters and get- 
ters is a recognized waste of time. 
Surely you have better things to do 
with your time. 

Another common form of conceptu- 
ally incorrect and equally wasteful test- 
ing is testing in a way that violates 
encapsulation, or more specifically, 
object integrity. Suppose you have a 
linked list for holding tokens, and sup- 
pose that rather than wrapping the list 
in its own class, as you should, you just 
use the bare data structure as it's pro- 
vided by the library. Then, in your test- 
ing, you write a test that adds an item 
to the list and immediately retrieves it. 
Then it tests the two versions for 
equality. 

What are you doing? You're actually 
testing the data structure provided 
by the system library. You are not test- 
ing your code, but rather a pair of 
methods encapsulated inside a data 
structure in a different library. That is 
never right. 



Integration Watch 



The desirability of 100% code cov- 
erage comes from an admirable but 
misdirected sense that unit testing the 
entire codebase improves the code's 
reliability. This, however, is not the 
case. Simply because unit tests bring 
value in one setting does not mean that 
an excess of tests is a valuable thing. 

However, for people in- 
clined in this direction, there 
is a testing need that's rarely 
discussed and rarely done, but 
which should gratify the 
desire to write tests: writing 
more than 100% coverage 
tests for certain methods. 

Greater than 100% is an 
easily achievable goal. For ex- 
ample, attaining 100% branch 
coverage often means that a 
given line needs to be tested multiple 
ways, resulting in more than 100% line 
coverage for that line. One hundred 
percent branch coverage is a desirable 
goal. You definitely want to make sure 
that every path your logic can take has 
been tested. If you aim for 100% 
branch coverage, you'll get very high 
line coverage and you'll probably be 
close to the maximum of the test cov- 
erage you need. 

There is an exception in certain 




routines where the logic is very com- 
plex. Let's take an example that in 
working code always generates high 
complexity values for its constituent 
routines: a parser. Parsers, like code 
generators, are not well served by unit 
tests. The way you gauge the quality of 
parsers is typically with integration 
tests. Many dyed-in-the- 
wool testers will insist that 
mixing unit tests with inte- 
gration tests is an error. It's 
not an error. At worst, it 
offends some testers' purity 
or sense of order. 

Regardless, writing tests 
that span several methods is 
frequently the only way to 
verify parser routines. And if 
you want to test your code 
thoroughly, you will need to shove a lot 
of meat into the parser grinder to see 
what kind of sausages you get on the 
other end. 

If you do this and carefully include 
the many edge cases, you will surely 
reach far, far more than 100% test cov- 
erage for the routines. You'll likely be in 
the thousands of percent. This is good 
and desirable. Even if the total applica- 
tion does not reach 100% coverage, this 
piling on in areas of high complexity is 



exactly what you want to be doing. 

Identification of complex code suit- 
able for super-testing relies on the 
common complexity metric called 
cyclomatic complexity (CMC), also 
called McCabe. It's not an ideal metric, 
but it is sufficient for our purposes. 

Many tools today can tell you the 
CMC of each method. (CMC should 
only be measured at the method level.) 
A project of the now-defunct Agitar 
Corp. used to suggest how much of a 
method's code must be tested at mini- 
mum in relation to its CMC. For CMC 
of 0-5, 0% code is the minimum, which 
strikes me at too low for CMC greater 
than 2. CMC 6-10 needs 42% coverage 
(still low). And so on, all the way to 
CMC >30, in which case no amount of 
testing coverage would meet minimum 
criteria. 

This is the key point. At CMC 30, 
you have to ref actor. But at CMC 
25-30, you want to super-test the code 
once you're certain there is no further 
useful refactoring. (For the curious, 
between CMC 11-25, Agitar suggests a 
range of 57% to 80%. Still too low, in 
my view. ) 

So don't shoot for 100% code cover- 
age; go for less overall, and in selected 
places, go for more. Much more. I 

Andrew Binstock is the principal analyst 
at Pacific Data Works. Read his blog at 
binstock.blogspot. com. 
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Finally, a Documentation Tool 
that Doesn't Forget the Developers 



ithor documentation in your favorite environment 
g., Microsoft Word, Adobe Drear 
K-To-Help's new built-in XML-based editor) 



ComponentOne® Doc-To-Help® is the Only • Embed context-sensitive Help in your applicati 

tool that helps developers and writers work and a ! low tech " ical writers t0 perform topi 

r ^ mapping visually 

seamlessly together to create deliverables 

• Generate automatic reference documentation 

that include Help, printed manuals, reference Microsoft Sandcastie 

documentation and more. Unlike most . Author documentation in your favorite environm 

documentation tools, Doc-To-Help (e.g., Microsoft Word, Adobe Drear 

. . . . .,. .. Doc-To-Help's new built-in XML-based editor) 

includes technology specifically 
designed for the developer. 

You get all this in one box! Imagine having one package that makes documentation 
simple for both the developer and the technical writer. 

Doc-To-Help 2009 

DOWNLOAD YOUR FREE TRIAL TODAY 

www.componentone.com/cometogether 



ComponentOne" 



ComponentOne Sales: 1.800.858.2739 or 1.412.681.4343 



Instantly 





♦ dozens of indexed, unindexed, fielded 
data and full-text search options 
(including Unicode support for hundreds 
of international languages) 

♦ file parsers / converters for 
hit-highlighted display of all popular 
file types 

♦ Spider supports static and dynamic web 
data; highlights hits while displaying 
links , formatting and images intact 

♦ API supports .NET, C++, Java, databases, 
etc. New .NET Spider API 



The Smart Choice for 
Text Retrieval® since 1991 



[ \S0 



Contact dtSearch for 
fully-functional evaluations 



♦ "Bottom line: dtSearch manages a 
terabyte of text in a single index 
and returns results in less than a 
second" - InfoWorld 

♦ "For combing through large 
amounts of data," dtSearch "leads 
the market" - Network Computing 

♦ dtSearch "covers all data sources ... 
powerful Web-based engines" 
-eWEEK 

♦ dtSearch "searches at blazing 
speeds" - Computer Reseller News 
Test Center 

See www.dtsearch.com for hundreds 
more reviews, and hundreds of 
developer case studies 



1-800- IT-FINDS • www.dtsearch.com 



www.sdtimes.com 
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Wishing on a star for resources 



I've had more than my normal amount 
of humiliation lately. Two new tech- 
nologies have recently entered my life: 
one centers on a microcontroller, the 
other on glass. The microcontroller is 
the ATmegal68, which powers the 
Arduino platform. Hardware is the new 
software, as least as far as hobbies go. 
Printing out "Hello World" is no longer 
enough to thrill a 13-year-old; now he or 
she demands making an LED blink. 

I know nothing about electronics; 
heck, I break into a cold sweat when 
adding RAM to a laptop. Nonetheless, to 
keep myself relevant to my nephews and 
nieces, I've become friends with the 
clerks at the local Radio Shack, who 
keep a straight face every time I bring 
another handful of random components 
up to the checkout counter. 

I make these visits because, when 
facing a project, I must get the precise 
components specified, down to the part 
number. I have no capacity for reasoning 
about circuit design, don't know if I can 
substitute an electrolytic for a ceramic 
capacitor, or how to keep the Magic 
Blue Smoke inside a transistor. (When 
the Magic Blue Smoke escapes, things 
stop working). 

Doug Teeple, a friend who converted 
his Karmann Ghia into a plug-in electric 



car (www.eghia.com), says one can "think 
in circuit components." But I am having a 
hard time finding resources. Books intro- 
ducing Arduino imply that software is the 
more mysterious part and concentrate on 
explaining loops and state manipulation 
using the C-like Processing language. 

Meanwhile, my imagination leaps for- 
ward to using "the fuzzy logic 
manifold editor" I built with 
Resolver One (see "Python: 
Arbitrarily interesting," Feb. 
1, p. 35) to generate code to 
control a belt-driven alt-az 
telescope mount when I can- 
not crawl beyond the simplest 
step-by-step projects. 

The telescope mount pro- 
ject is precise because of my 
other humbling hobby. In 
contrast with electronics, I have some 
familiarity with astronomy. Like many 
geeks, I had a few mall-store telescopes 
growing up, and know enough stars to 
tell Scorpio from the Pleiades (or as the 
Hawaiians view them, to tell Maui's fish- 
hook from his kite). 

Optics ain't cheap. My choice to step 
into the world of "real" amateur astrono- 
my required a number of monetary 
trade-offs, one of which was the decision 
to buy a relatively inexpensive manual 




mount. Today, you can spend a pretty 
penny on a computer-integrated mount 
that understands its location and orienta- 
tion. Such "goto" mounts are undoubted- 
ly impressive (and necessary for 
astrophotography), but experts say that 
manual "star hopping" is both sufficient 
and more satisfying. 

Well. Looking through a 
decent telescope is similar to 
flying into the monolith in 
"2001: A Space Odyssey" — it's 
full of stars, pinpoints whose 
relative brightness becomes 
difficult to perceive. Slewing 
more than a field-of-view at a 
time requires ignoring the 
image-reversed evidence of 
your eyes. The slightest break 
in concentration, and you 
become lost in the Milky Way. 

Anticipating the challenges faced by 
newcomers (including yourself) is one of 
the easiest things to get wrong in educa- 
tion. By averaging out the challenges of 
the many, it's easy to fail to serve the 
needs of an individual. The challenge in 
Arduino hacking is writing software. Star 
hopping is more satisfying if you have 
many decades of astronomy in front of 
you. Test-driven development is more 
productive than plunging into the appli- 



Larry 
O'Bmn 



cation code. These things all may be true 
in the aggregate, but the experience of 
beginning is intensely personal. 

For Arduino, I wish there were a 
"Head-First Circuit Design" book. For 
amateur astronomy, I wish there were 
"build your own goto mount" projects. 
On the other side of the coin, experts are 
blind to what resources are missing for 
teaching modern software development 
techniques. On the Internet, what you 
tend to find are either technically deep 
resources (experts writing for them- 
selves and their peers) or rehashes of 
very basic, very traditional paths ("Hello 
World" and blinking LEDs). 

Although blogging is passe (Twitter 
provides a higher distraction-effort 
ratio), I think it's tremendously impor- 
tant for education. Blog (and podcast 
and videocast) about what you know and 
how you think about problems. You 
don't have draft a textbook on the sub- 
ject, nor do you have to create a unique 
network-ready comic persona. Circuit 
hacking, astronomy and software devel- 
opment are all areas that require sites 
that are technically precise, but which 
also beg for more voices and viewpoints. 
And don't be afraid of being wrong: 
Someone told me that the technical 
term is simply Magic Smoke. I 

Larry O'Brien is a technology consul- 
tant, analyst and writer. Read his blog at 
www. knowing, net. 
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PERFECTION IN SOFTWARE PROTECTION 



Exceptional Software Protection- 






CodeMeter for .NET 



More than 1000 Key-Storage License Entries 

Different ISV's can share one dongle 

Secure Expiration Date with a Real-Time-Clock 

Unique Time Certification Feature 

Control Relative and/or Absolute time 

More ways to sell = More sales 

Create Student and Version Licenses 



Control Network Licensing 
Control concurrent users 
Control "roaming" users 
Create "Standby" Licenses 
Hot Standby and Cold Standby 
Provide Overflow Licenses 

Pay-Per-Use Counter 



WIBU-SYSTEMS USA Inc. 

110W Dayton Street, 
Edmonds, WA 98020 
United States 
www.wibu.us 
info@wibu.us 
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MICROSOFT'S SAM RAM J I was insis- 
tent on having a dialog with the Software 
Freedom Law Centers Bradley Kuhn. 
Ramji believes that it is important for 
Microsoft to articulate its position on the 
GPL and to clear up any "misconcep- 
tions" that its critics have. 

Unfortunately, Ramji was unable to 
comment further by press time, but he 
has promised a response to some of 
Kuhn's more cutting remarks. 

Due to its actions in the not-so-dis- 
tant past, Microsoft has a long way to go 
to earn the trust of open-source advo- 
cates like Kuhn. It is encouraging that 
both Kuhn and Ramji were willing to 
have an amicable dialogue. I'm going to 
continue to drive the conversation, and 
you, our readers, can come to your own 
conclusions. - David Worthington 

IT'S SOMEWHAT IRONIC that the 
founder of the free software movement 
is jealous of one of the primary figures 
within the movement. When I inter- 
viewed Richard Stallman for this month s 
cover story, I had lots of questions to ask. 
But one that wasn't on my list was, "What 
do you think of Linus Torvalds?" 

No matter; Stallman took the time to 
answer this question without my ever hav- 
ing to ask it. His answer? He doesn't like 
the man at all. I got a 10-minute earful 
about how Torvalds doesn't believe in free 
software, doesn't care about licenses and 
doesn't deserve the credit for building the 
largest GPL project out there. 

For a guy who's built a whole move- 
ment based on working together and col- 
laborating, Stallman is certainly not happy 
about sharing the spotlight. - Alex Handy 
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SHAREPOINT CONFERENCE DEBUT A 
SUCCESS IN SF, NEXT STOP: BOSTON 



The brightest stars in the 
SharePoint firmament came 
together share their experi- 
ences and insights at the 
three-day SharePoint Technol- 
ogy Conference, presented by 
BZ Media in late January. 

The conference, held near 
San Francisco, featured more 




Companions have been extend- 
ed for the rest of the Microsoft 
Office clients, allowing Word or 
PowerPoint files to be modified 
in a browser, and that WAC will 
have the same ribboning expe- 
rience in the browser as it does 
on the desktop. 

Rizzo also talked about the 



than 60 technical workshops Microsoft's Tom Rizzo future of SharePoint, saying 



and classes designed to discusses the future 
instruct developers, IT admin- of the platform in his 
istrators and business informa- keynote, touching on 
tion workers in the technigues "SharePoint 14." 
reguired to optimize an organi- 
zation's SharePoint implementation. 
More than 20 companies were on hand to 
demonstrate how their products can 
extend SharePoint. 

Microsoft's senior director of Share- 
Point, Tom Rizzo, kicked off the event with 
a keynote that hinted at some new fea- 
tures and capabilities in "SharePoint 14," 
which has been released in alpha form to 
a select few customers to work out. Rizzo 
explained that Microsoft's Web Access 



the company is investing in 

services that sit around the 

Azure cloud-based operating 

system, and SharePoint Online, 

which will address such issues 

as how to connect Active Directory to the 

cloud via a federation gateway. The goal, 

he said, is to make SharePoint Online as 

fully featured as a SharePoint Server that 

would be installed in an enterprise. 

More than 600 people attended the 
conference, held at the Hyatt Regency 
San Francisco Airport. 

The next SPTEchCon will be in Boston 
on June 22-24, 2009. Learn more at 
SPTechCon.com. I —David Rubinstein 



BUSINESS BRIEFS 




GOOGLE DROPPED, VMWARE GREW 

Talend, a provider of open-source data integration software, closed 
a US$12 million round of funding, led by London-based venture firm 
Balderton Capital and private investor Bernard Liautaud, founder 
of SAP-owned Business Objects. 

This is the third round of funding for the company, which 
launched its first product in August 2005 and has seen approxi- 
mately 3.3 million downloads of its Talend Open Studio since Octo- 
ber 2006, according to Yves de Montcheuil, vice president of mar- 
keting. With the new funding, Talend is "ready to scale our business 
model. We think the timing's perfect. Our solution, and open source 
in general, helps restrain costs," de Montcheuil said. Like many 
open-source companies, Talend gives its software away but sells 
add-ons and service/support contracts. 

Talend Open Studio, now at version 3.0, is the company's main 
data ETL and integration product. A subscription-based Integra- 
tion Suite adds a multi-user repository and auto-deployment fea- 
tures capable of load balancing. Talend OnDemand is the compa- 
ny's software-as-a-service solution, while Talend Data Quality is 
the management piece. 

With Balderton and Liautaud providing what Talend CEO 
Bertrand Diard called "very deep pockets," the company is poised 
to compete more aggressively in the data integration market and 



add to its paying customer base of more than 400, he said. Liau- 
taud engineered the sale of Business Objects to SAP for $6.75 bil- 
lion in 2007. "When an entrepreneur like Bernard comes on board, 
his knowledge is very important to us," Diard said. 

Meanwhile, Balderton, then known as Benchmark Capital 
Group, was an early investor in MySQL and took a huge windfall 
when Sun purchased the open-source database for $1 billion in 
January 2008. Diard called that the most successful venture cap- 
ital exit in the history of open source. 

"We are now ready to play," Diard said of competing with mar- 
ket stalwarts CA, IBM and Pervasive Software. "We are well- 
equipped to fight." 

EARNINGS: Google's net income for the fourth quarter of 2008 
dropped significantly to US$382 million, compared to $1.29 billion 
in the third quarter of 2008. Google reported revenues of $5.7 bil- 
lion for the quarter ended Dec. 31, an increase of 18% compared to 
the fourth quarter of 2007 and a 3% jump compared to the third 
quarter of 2008 . . . VMware announced revenue for fiscal year 
2008 of US$1.9 billion, an increase of 42% from 2007. Income for 
fiscal year 2008 was $313 million, an increase of 33% from 2007. 
Additionally, revenues for the fourth quarter of 2008 were $515 
million, an increase of 25% from the fourth quarter of 2007. 1 



EVENTS CALENDAR 



Southern California 


February 20-22 


Linux Expo 




Los Angeles 




SCALE INC. 




scale7x.socallinuxexpo.org 




FutureTest 2009 


February 24-25 


New York 




REDWOOD COLLABORATIVE MEDIA 


futuretest.net 




Emerging Technology 


March 9-12 


Conference 




San Jose 




O'REILLY MEDIA 




en.oreilly.com/et2009 




SD West 


March 9-13 


Santa Clara 




THINK SERVICES 




www.sdexpo.com 




SaaS Summit 


March 11-13 


San Francisco 




OPSOURCE 




saassummit09.net 




MIX09 


March 18-20 


Las Vegas 




MICROSOFT 




2009.visitmix.com 




EclipseCon 2009 


March 23-26 


Santa Clara 




ECLIPSE FOUNDATION 




www.eclipsecon.org 




Game Developers 


March 23-27 


Conference 




San Francisco 




THINK SERVICES 




www.gdconf.com 




PyCon 


March 27-29 


Chicago 




PYTHON SOFTWARE FOUNDATION 


us.pycon.org/2009 




STPCon Spring 


March 31— April 2 


San Mateo, Calif. 




REDWOOD COLLABORATIVE MEDIA 


www.stpcon.com 




Web 2.0 Expo 


March 31— April 3 


San Francisco 




O'REILLY MEDIA 




en.oreilly.com/webexsf2009 




MySQL Conference 


April 20-23 


and Expo 




Santa Clara 




O'REILLY MEDIA 




www.mysqlconf.com 




RSA Conference 


April 20-24 


San Francisco 




RSA 




365.rsaconference.com 




RailsConf 


May 4-7 


Las Vegas 




O'REILLY MEDIA 




en.oreilly.com/rails2009 




Micro Focus World 


May 11-13 


Dallas 




MICRO FOCUS 




www.microfocusworld.com 




SPTechCon 


June 22-24 


Boston 




BZ MEDIA 




www.sptechcon.com 





For a more complete calendar of U.S. software 
development events, see www.sdtimes.com/calendar. 
Information is subject to change. Send news about 
upcoming events to events@bzmedia.com. 



Software Development Times (ISSN 1528-1965) is published 24 times per year by BZ Media LLC, 7 High St., Ste. 407, Huntington, NY 11743. Periodicals postage paid at Huntington, NY, and additional offices. SD Times is a registered trademark of BZ Media LLC. All contents © 2009 BZ Media LLC. 
All rights reserved. The price of a one-year subscription is US$179 for subscribers in the U.S., $189 in Canada, $229 elsewhere. POSTMASTER: Send address changes to SD Times, PO Box 2169, Skokie, IL 60076. SD Times subscriber services may be reached at sdtimes@halldata.com or by calling +1-847-763-9692. 
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STUDIO FOR SILVERLIGHT 

STOCK PORTFOLIO DEMO 



Studio for Silverlight 

INCLUDES 30+ SILVERLIGHT CONTROLS 

Display rich, interactive geographical information 
using CI Maps 

Create full-featured, animated data visuals with C1 Chart 

• Develop complex dashboards easily with 
C1 LinearGauge and C1 RadialGauge 

• NEW Incorporate animated GIF files to your apps 
with CI Image 

• NEW Add context menu support to your apps using 
OContextMenu 

StudioforASP.NET 

COMPLETELY RE-ENGINEERED 

Fully exploits the AJAX Framework 

• Rich client-side object model 
3x smaller footprint 
1 0x faster performance 
Cross-browser support 
Built-in visual styles and animation effects 

NEW Studio for iPhone 

FIRST SUITE OF IPHONE-ENHANCED WEB CONTROLS— CTP AVAILABLE 

• Build iPhone Web apps that look and feel like the 
native Ul 

Includes design elements for menus, Ul buttons, content 
controls, sliders, and more 
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Studio Enterprise 2008 v3 delivers 
exactly what you need to produce next- 
generation Uls for the Web. 






ComponentOne* 

Studio 
Enterprise 2008v3 

GET STARTED TODAY download your free trial @ 

componentone.com/amazingweb 




idbars 



WinForms WPF ASP.NET Silverlight iPhone Mobile ActiveX 



;omponen 



ComponentOne Sales 

1 .800.858.2739 or 1 .41 2.681 .4343 



987-2009 ComponentOne 
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Advanced Digital Dashboards Require 
Advanced Data Visualization 
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Data Visualization 
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Available for Visual Studio 2008 & SQL Server 2008 Reporting Services 

Build Custom Executive Dashboards With Data Visualization Solutions From Dundas! 

As the leader in data visualization solutions for .NET, SharePoint 2007 and SQL Server Reporting Services 2005 & 2008, Dundas offers the latest 
award-winning chart, gauge and map technologies. See why Fortune 500 companies around the globe trust Dundas to create advanced custom 
dashboard applications. 

For customers requiring additional assistance, Dundas Consulting offers unmatched expertise and experience in creating and optimizing digital 
dashboards and their supporting infrastructure. Our team of highly specialized software consultants and graphic artists can help you jump start 
your dashboard initiative, build your complete system or simply advise you on all the tasks associated with bringing a dashboard system to life. 

To see for yourself how Dundas products can improve your applications, download full evaluation copies of Dundas Chart, Gauge and Map from 
www.dundas.com/downloads. 
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Chart Gauge Map 



Available for: 



[ 



SharePoint 2007 



.NET 



SQL Server Reporting Services 



Microsoft 

GOLD CERTIFIED | Data Management Solutions 
Partner 



www.dundas.com 

Microsoft, SharePoint, SQL Server and Visual Studio are registered trademarks of Microsoft Corporation in the United States and/or other countries 



www.dundas.com 
info@dundas.com 
(416)467-5100 



Advanced Data Visualization for Microsoft® Technologies 



